Back to vendor advisories
Palo Alto Networks Security AdvisoriesPAN-SA-2026-0006

PAN-SA-2026-0006: Informational Bulletin: Impact assessment of OSS CVEs in PAN-OS

The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to PAN-OS software. While PAN-OS software may include the affected OSS package, PAN-OS does not offer any scenarios required for an attacker to successfully exploit these vulnerabilities and is not impacted.

0.0CVSS out of 10Informational severity
Scope

What the vendor says is affected

  • PAN-OS

Versions the vendor lists as fixed

  • PAN-OS All
Next step

What the vendor recommends

The OSS CVEs are fixed in the respective PAN-OS versions.

Review the complete instructions on the vendor's site
Timeline

When this advisory changed

  1. Published by Palo Alto Networks

    The publication date reported by the vendor.

  2. Added to SecurityAlert

    We collected the advisory from the official source.

  3. Confirmed at the source

    Our collector saw this advisory during a later source check.